Falhas do tipo CWE-78

4.629 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2023-35961HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2026-9862CRITICALCore Privileged Access Manager (BoKS) autoregistration service command injection vulnerabilityEPSS 1.5%CVE-2021-31799HIGHIn RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a EPSS 1.5%CVE-2026-0795HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.5%CVE-2021-34352HIGHCommand Injection Vulnerability in QVREPSS 1.5%CVE-2022-21191HIGHVersions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checEPSS 1.5%CVE-2026-26280HIGHSysteminformation has a Command Injection via unsanitized interface parameter in wifi.js retry pathEPSS 1.5%CVE-2022-40740HIGHRealtek GPON router - Command InjectionEPSS 1.5%CVE-2023-31198HIGHOS command injection vulnerability exists in Wi-Fi AP UNIT allows. If this vulnerability is exploited, a remote authenticated attacker with EPSS 1.5%CVE-2024-50374CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.5%CVE-2024-50370CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.5%CVE-2023-28742HIGHBIG-IP iQuery mesh vulnerabilityEPSS 1.5%CVE-2022-27489HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, EPSS 1.5%CVE-2023-2091HIGHKylinSoft youker-assistant adjust_cpufreq_scaling_governer os command injectionEPSS 1.5%CVE-2024-27516CRITICALServer-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obEPSS 1.5%CVE-2026-25195HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2021-38685CRITICALCommand Injection Vulnerability in VioStorEPSS 1.5%CVE-2021-34351CRITICALCommand Injection Vulnerability in QVREPSS 1.5%CVE-2021-34348CRITICALCommand Injection Vulnerability in QVREPSS 1.5%CVE-2026-23774HIGHDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 1.5%